Chinese Threat Actor UAT-10147 Uses AI to Accelerate Attacks with SPECTRE Malware
Cisco Talos published research on August 20, 2026, detailing UAT-10147, a Chinese-speaking threat actor conducting high-severity intrusion campaigns against government, education, and technology organizations worldwide. The group exploits known vulnerabilities in internet-facing web servers to gain initial access, then deploys a cross-platform implant called SPECTRE alongside rootkits and remote access tools on both Windows and Linux systems. A distinguishing feature of this campaign is the attacker's use of AI tools to rapidly debug exploit code, analyze failures, and automate web shell deployment across a target list of approximately 170,000 URLs. On Windows, indicators include unauthorized admin accounts, modified Defender exclusions, and suspicious RDP activity, while on Linux, anomalous kernel modules signal compromise. Security teams are advised to prioritize patching public-facing servers, as unpatched known vulnerabilities serve as the primary entry point for this threat actor.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in